Логотип exploitDog
bind:"CVE-2022-41915"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-41915"

Количество 8

Количество 8

ubuntu логотип

CVE-2022-41915

около 3 лет назад

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-41915

около 3 лет назад

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-41915

около 3 лет назад

Netty project is an event-driven asynchronous network application fram ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hh82-3pmq-7frp

около 3 лет назад

Netty vulnerable to HTTP Response splitting from assigning header value iterator

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-00183

около 3 лет назад

Уязвимость сетевого программного средства Netty, связанная с возникновением конфликта интерпретаций, позволяющая нарушителю раскрыть и модифицировать защищаемую информацию

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2096-2

больше 2 лет назад

Security update for netty, netty-tcnative

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2096-1

больше 2 лет назад

Security update for netty, netty-tcnative

EPSS: Низкий
redos логотип

ROS-20240514-04

больше 1 года назад

Множественные уязвимости netty

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-41915

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-41915

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-41915

Netty project is an event-driven asynchronous network application fram ...

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-hh82-3pmq-7frp

Netty vulnerable to HTTP Response splitting from assigning header value iterator

CVSS3: 6.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2024-00183

Уязвимость сетевого программного средства Netty, связанная с возникновением конфликта интерпретаций, позволяющая нарушителю раскрыть и модифицировать защищаемую информацию

CVSS3: 6.5
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2096-2

Security update for netty, netty-tcnative

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2096-1

Security update for netty, netty-tcnative

больше 2 лет назад
redos логотип
ROS-20240514-04

Множественные уязвимости netty

CVSS3: 7.5
больше 1 года назад

Уязвимостей на страницу